Live data from Hacker News

WiFi deauthentication attacks and home security

mjg59.dreamwidth.org

61–70 of 232 posts

Re: WiFi deauthentication attacks and home security

#61

Earlier quoted context omitted.

they want privacy?

I can't see how screwing up the internet for everyone else improves your own privacy.

> screwing up the internet for everyone else

Unless you're on ethernet, then you suffer none of wifi's many downsides.

Re: WiFi deauthentication attacks and home security

#62
post #61

Earlier quoted context omitted.

I can't see how screwing up the internet for everyone else improves your own privacy.

> screwing up the internet for everyone else Unless you're on ethernet, then you suffer none of wifi's many downsides.

I don't get the point of this post - are you saying deauth attacks are fine and everyone should just abandon Wi-Fi?

Re: WiFi deauthentication attacks and home security

#63
post #57

People send deauth packets just for fun, as part of social networking. While it is fun for the sender, the those that are affected, are probably very annoyed. https://pwnagotchi.ai/

Just beware that in many jurisdictions using that thing on other people's devices is punishable by serious jail terms. Sometimes even possession of such a device.

Re: WiFi deauthentication attacks and home security

#64
post #61

Earlier quoted context omitted.

> screwing up the internet for everyone else Unless you're on ethernet, then you suffer none of wifi's many downsides.

I don't get the point of this post - are you saying deauth attacks are fine and everyone should just abandon Wi-Fi?

I am saying not everyone is affected, only those who solely rely on wifi. Others have realized that a shared medium with questionable security is inherently unreliable and have other options at their disposal.

Re: WiFi deauthentication attacks and home security

#65
post #39

In Norway/Oslo there is a lot of people with equipment sending deauthentication packages, jamming neighboring equipment, and one of the main reason for slow Internet (lot of jitter). Did some research on this together with The Norwegian Communications Authority (NKOM) to isolate the problem. If you want to check for yourself if someone close by i sending deauthentication packages; fire up a Mac and: 1. Open Wi-Fi-dia…

Why are people actually doing this on a wide scale?

I can think of 2 potential reasons but neither seems satisfying. The first would be state agencies testing attack vectors in real life. Would suck to send out an agent who commits their crime 100% flawlessly only for them to get caught by some unsecured doorbell or other random internet device. The second would be attempts to force increases in security through intentional hacks and sabotage.

Although if someone can think of better reasons I would love to hear it.

Re: WiFi deauthentication attacks and home security

#66
Seems widespread; sad state of affairs... wonder how many locations suffer from (mis)configured APs battling each other..

https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortig...

"In addition to monitoring rogue APs, you can actively prevent your users from connecting to them. When suppression is activated against an AP, the FortiGate WiFi controller sends deauthentication messages to the rogue AP’s clients, posing as the rogue AP, and also sends deauthentication messages to the rogue AP, posing as its clients."

Re: WiFi deauthentication attacks and home security

#67
post #32
post #29

Does that mean you can monitor when someone is pushing your neighbors' ring bell?

You can certainly detect when your neighbour's doorbell is streaming video, yes.

Interesting, you could use it to turn your neighbors devices into unintentional motion detection sensors without them ever knowing. You could use it for foot traffic analysis or something.

Re: WiFi deauthentication attacks and home security

#68
post #39

Earlier quoted context omitted.

Why are people actually doing this on a wide scale?

I can think of 2 potential reasons but neither seems satisfying. The first would be state agencies testing attack vectors in real life. Would suck to send out an agent who commits their crime 100% flawlessly only for them to get caught by some unsecured doorbell or other random internet device. The second would be attempts to force increases in security through intentional hacks and sabotage. Although if someone can…

Maybe an unethical Wi-Fi manufacturer thought they were clever to deauth clients of APs with MACs not in their own range, to clear other traffic off the band they use and have their products perform better than others by means of sabotage.

Re: WiFi deauthentication attacks and home security

#69
post #54

Earlier quoted context omitted.

> For Netherlands: You cannot just have a camera recording the public. Though there's a bit of leeway, meaning if you have a camera recording your property it's logical that it'll record a bit of the road. You just have to minimize that bit. This is simply not at all true. You can film anything you want in public. I believe the laws around publishing photographs or films of other people is a bit more complex though.

Pointing a permanent security camera at a public space as a private person really is illegal. This is different from occasionally using a handheld camera. Because one is surveillance that is meaningfully different from what you could do just by watching someone, and the other is not (this is my argument, not sure whether this is the legal argument in NL)

Well that scenario is prohibited by the GDPR (though I’m not sure if different authorities would have differing views on that). But the statement that you cannot film public scenes or the people who happen to be in them is simple false.

Re: WiFi deauthentication attacks and home security

#70

I think the title should be changed to something like "how to protect your privacy with Wifi deauthentication". Incidentally, I was considering one of these devices as an addition to my home automation setup, then I realized that it would not be cool to monitor every person getting out of the elevators on my floor.

What if someone were to offer you, oh, $50/mo for that feed?
Post reply on HN